Existing techniques to detect kernel-level rootkits expose some infections, but they don't identify specific attacks. This rootkit categorization approach helps system administrators identify the extent of specific infections, aiding in optimal recovery and faster reactions to future attacks.
Index Terms:
Invasive software, rootkits, rootkit
Citation:
John G. Levine, Julian B. Grizzard, Henry L. Owen, "Detecting and Categorizing Kernel-Level Rootkits to Aid Future Detection," IEEE Security and Privacy, vol. 4, no. 1, pp. 24-32, Jan./Feb. 2006, doi:10.1109/MSP.2006.11